Infostealer Trojan
In short: An infostealer steals saved passwords, cookies, crypto wallets and other data from the infected device.
In more detail: Known families: RedLine, Raccoon, Vidar. They read browser passwords, session cookies, autofill data and wallet files and send them to the attackers.
In Depth
Why cookies are dangerous
A stolen session cookie can take over a logged-in session, even without the password and sometimes despite MFA (session hijacking, see hijacking).
Protection
Do not store passwords in the browser but in a password manager with a master password. End sessions regularly, use only trusted software, change stolen credentials immediately.